najde se nejaky dobrodinec a zkoukne toto ?
Napsal: 07 srp 2009 09:28
ComboFix 09-08-04.03 - Jakub 07.08.2009 8:17.1.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1535.1087 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jakub\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090806-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\b1fc45.msi
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((( Soubory vytvořené od 2009-07-07 do 2009-08-07 )))))))))))))))))))))))))))))))
.
2009-08-06 12:54 . 2009-08-06 12:54 -------- d-----w- c:\program files\CCleaner
2009-08-06 08:45 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-06 08:45 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-06 08:45 . 2009-08-06 08:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-06 08:04 . 2009-08-06 08:04 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-06 08:03 . 2009-08-06 08:03 -------- d-----w- c:\program files\MSBuild
2009-08-06 08:03 . 2009-08-06 08:03 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 08:02 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 08:02 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-06 08:02 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 08:02 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-06 08:02 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 08:02 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 08:02 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-06 08:02 . 2009-08-06 08:03 -------- d-----w- C:\b46581a9c0db01d955e75893bf
2009-08-06 07:56 . 2009-08-06 07:56 -------- d-----w- c:\program files\MSXML 6.0
2009-07-22 21:43 . 2009-07-22 21:43 -------- d-sh--w- C:\found.000
2009-07-15 09:41 . 2009-07-15 09:41 -------- d-----w- C:\66915fac3c7008d3528d4e3b9601ac
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-06 08:48 . 2008-07-25 09:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-06 08:11 . 2001-10-25 14:00 79062 ----a-w- c:\windows\system32\perfc005.dat
2009-08-06 08:11 . 2001-10-25 14:00 432004 ----a-w- c:\windows\system32\perfh005.dat
2009-08-03 10:17 . 2008-08-08 14:46 189104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-03 10:08 . 2008-08-08 14:46 139584 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-29 07:41 . 2008-09-30 12:28 -------- d-----w- c:\program files\Oberon Media
2009-07-29 07:41 . 2008-06-27 08:21 -------- d-----w- c:\program files\Realore
2009-07-18 10:45 . 2009-06-18 17:01 -------- d-----w- c:\program files\PhotoFiltre
2009-07-04 12:50 . 2008-08-08 14:46 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-07-04 11:26 . 2008-12-24 12:55 -------- d-----w- c:\program files\Jojos Fashion Show 2
2009-07-04 11:23 . 2008-09-26 14:12 -------- d-----w- c:\program files\VirtualDJ
2009-07-04 11:11 . 2008-11-22 14:47 -------- d-----w- c:\program files\Počítačový Svět Pohádek
2009-07-04 11:10 . 2008-12-23 08:43 -------- d-----w- c:\program files\Fashion Solitaire
2009-07-04 11:10 . 2008-06-30 20:31 -------- d-----w- c:\program files\AT&T WorldNet Setup
2009-07-04 11:10 . 2005-01-16 23:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-04 11:05 . 2008-07-02 07:39 -------- d-----w- c:\program files\Activision
2009-07-04 09:48 . 2009-07-04 09:48 -------- d-----w- c:\program files\Electronic Arts
2009-07-04 09:47 . 2009-07-04 09:47 1612 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-07-04 09:30 . 2009-07-04 09:30 -------- d-----w- c:\program files\EA Games
2009-06-29 16:00 . 2004-08-17 13:49 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:59 . 2004-08-17 13:49 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:59 . 2004-08-17 13:49 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:55 . 2004-08-17 13:49 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2001-10-25 14:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2004-08-17 13:49 1293312 ----a-w- c:\windows\system32\quartz.dll
2009-05-29 05:16 . 2009-05-23 12:55 682280 ----a-w- c:\windows\system32\pbsvc.exe
2009-05-23 13:02 . 2009-05-23 13:02 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-23 12:41 . 2009-05-23 12:41 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-03-01 172792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2002-09-24 73728]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-27 593920]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-03 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2-2\\CoD2MP_s.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2 Trial Version\\zt2demoretail.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 St323dk;St323dk;c:\windows\system32\drivers\st323dk.sys [13.10.2002 20:24 88736]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23.6.2008 22:10 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.6.2008 22:10 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [13.3.2009 15:56 222456]
.
Obsah adresáře 'Naplánované úlohy'
2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
.
.
------- Doplňkový sken -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.seznam.cz/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search - ?p=ZSman000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-07 08:27
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-606747145-179605362-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:eb,0a,dd,6c,3f,6d,27,65,0d,26,d3,e2,03,61,05,0d,05,6e,47,8b,63,
d0,c3,48,42,50,cf,e5,1a,25,db,e0,ad,f1,88,a9,d7,52,3c,8a,7c,62,d6,7c,97,65,\
"rkeysecu"=hex:c5,0e,97,c1,1f,e4,a6,1d,b7,5a,ce,4b,76,83,60,b0
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Celkový čas: 2009-08-07 8:34 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-08-07 06:34
Před spuštěním: Volných bajtů: 39 191 658 496
Po spuštění: Volných bajtů: 44 200 169 472
162 --- E O F --- 2009-08-07 06:15
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1535.1087 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jakub\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090806-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\b1fc45.msi
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((( Soubory vytvořené od 2009-07-07 do 2009-08-07 )))))))))))))))))))))))))))))))
.
2009-08-06 12:54 . 2009-08-06 12:54 -------- d-----w- c:\program files\CCleaner
2009-08-06 08:45 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-06 08:45 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-06 08:45 . 2009-08-06 08:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-06 08:04 . 2009-08-06 08:04 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-06 08:03 . 2009-08-06 08:03 -------- d-----w- c:\program files\MSBuild
2009-08-06 08:03 . 2009-08-06 08:03 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 08:02 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 08:02 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-06 08:02 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 08:02 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-06 08:02 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 08:02 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 08:02 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-06 08:02 . 2009-08-06 08:03 -------- d-----w- C:\b46581a9c0db01d955e75893bf
2009-08-06 07:56 . 2009-08-06 07:56 -------- d-----w- c:\program files\MSXML 6.0
2009-07-22 21:43 . 2009-07-22 21:43 -------- d-sh--w- C:\found.000
2009-07-15 09:41 . 2009-07-15 09:41 -------- d-----w- C:\66915fac3c7008d3528d4e3b9601ac
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-06 08:48 . 2008-07-25 09:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-06 08:11 . 2001-10-25 14:00 79062 ----a-w- c:\windows\system32\perfc005.dat
2009-08-06 08:11 . 2001-10-25 14:00 432004 ----a-w- c:\windows\system32\perfh005.dat
2009-08-03 10:17 . 2008-08-08 14:46 189104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-03 10:08 . 2008-08-08 14:46 139584 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-29 07:41 . 2008-09-30 12:28 -------- d-----w- c:\program files\Oberon Media
2009-07-29 07:41 . 2008-06-27 08:21 -------- d-----w- c:\program files\Realore
2009-07-18 10:45 . 2009-06-18 17:01 -------- d-----w- c:\program files\PhotoFiltre
2009-07-04 12:50 . 2008-08-08 14:46 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-07-04 11:26 . 2008-12-24 12:55 -------- d-----w- c:\program files\Jojos Fashion Show 2
2009-07-04 11:23 . 2008-09-26 14:12 -------- d-----w- c:\program files\VirtualDJ
2009-07-04 11:11 . 2008-11-22 14:47 -------- d-----w- c:\program files\Počítačový Svět Pohádek
2009-07-04 11:10 . 2008-12-23 08:43 -------- d-----w- c:\program files\Fashion Solitaire
2009-07-04 11:10 . 2008-06-30 20:31 -------- d-----w- c:\program files\AT&T WorldNet Setup
2009-07-04 11:10 . 2005-01-16 23:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-04 11:05 . 2008-07-02 07:39 -------- d-----w- c:\program files\Activision
2009-07-04 09:48 . 2009-07-04 09:48 -------- d-----w- c:\program files\Electronic Arts
2009-07-04 09:47 . 2009-07-04 09:47 1612 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-07-04 09:30 . 2009-07-04 09:30 -------- d-----w- c:\program files\EA Games
2009-06-29 16:00 . 2004-08-17 13:49 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:59 . 2004-08-17 13:49 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:59 . 2004-08-17 13:49 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:55 . 2004-08-17 13:49 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2001-10-25 14:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2004-08-17 13:49 1293312 ----a-w- c:\windows\system32\quartz.dll
2009-05-29 05:16 . 2009-05-23 12:55 682280 ----a-w- c:\windows\system32\pbsvc.exe
2009-05-23 13:02 . 2009-05-23 13:02 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-23 12:41 . 2009-05-23 12:41 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-03-01 172792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2002-09-24 73728]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-27 593920]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-03 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2-2\\CoD2MP_s.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2 Trial Version\\zt2demoretail.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 St323dk;St323dk;c:\windows\system32\drivers\st323dk.sys [13.10.2002 20:24 88736]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23.6.2008 22:10 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.6.2008 22:10 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [13.3.2009 15:56 222456]
.
Obsah adresáře 'Naplánované úlohy'
2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
.
.
------- Doplňkový sken -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.seznam.cz/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search - ?p=ZSman000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-07 08:27
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-606747145-179605362-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:eb,0a,dd,6c,3f,6d,27,65,0d,26,d3,e2,03,61,05,0d,05,6e,47,8b,63,
d0,c3,48,42,50,cf,e5,1a,25,db,e0,ad,f1,88,a9,d7,52,3c,8a,7c,62,d6,7c,97,65,\
"rkeysecu"=hex:c5,0e,97,c1,1f,e4,a6,1d,b7,5a,ce,4b,76,83,60,b0
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Celkový čas: 2009-08-07 8:34 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-08-07 06:34
Před spuštěním: Volných bajtů: 39 191 658 496
Po spuštění: Volných bajtů: 44 200 169 472
162 --- E O F --- 2009-08-07 06:15